<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T06:17:31.034795+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-362174</id>
    <title>EUVD-2026-362174</title>
    <updated>2026-10-08T06:17:31.037330+00:00</updated>
    <content>EUVD-2026-362174</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-362174"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55569</id>
    <title>fkie_cve-2026-55569</title>
    <updated>2026-10-08T06:17:31.037379+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>aqua is a declarative command-line version manager written in Go. Prior to 2.60.1, pkg/unarchive/archives.go in the handler.HandleFile method calls os.Symlink with archives.FileInfo.LinkTarget without verifying that the target remains under the extraction destination. A later regular-file entry at the same archive path is opened with OpenFile using O_CREATE and O_WRONLY, which follows the attacker-planted symlink. A malicious or compromised package archive can therefore write attacker-controlled bytes outside aqua's extraction directory with the privileges of the user running aqua, potentially overwriting shell startup files, tool configuration, or writable executable paths. This issue is fixed in version 2.60.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55569"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mf5c-hw34-4hpp</id>
    <title>GHSA-mf5c-hw34-4hpp — Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory</title>
    <updated>2026-10-08T06:17:31.037434+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/aquaproj/aqua/v2</p>
<p>### Summary</p>
<p>`aquaproj/aqua` extracts downloaded tool archives through `pkg/unarchive/archives.go` using `github.com/mholt/archives`. The archive handler creates symlink entries with `os.Symlink(f.LinkTarget, dstPath)` without validating that the symlink target resolves inside the extraction destination. A subsequent regular-file archive entry with the same path is opened with `OpenFile(dstPath, O_CREATE|O_WRONLY)`, which follows the attacker-planted symlink.</p>
<p>A malicious or compromised aqua package / release asset can therefore write attacker-controlled bytes outside aqua's extraction directory, with the privileges of the user running aqua.</p>
<p>### Details</p>
<p>Affected file: `pkg/unarchive/archives.go`</p>
<p>Affected function: `(*handler).HandleFile`</p>
<p>The vulnerable logic is the combination of:</p>
<p>```go
os.Symlink(f.LinkTarget, dstPath)
```</p>
<p>for symlink entries, followed by:</p>
<p>```go
h.fs.OpenFile(dstPath, os.O_CREATE|os.O_WRONLY, f.Mode())
```</p>
<p>for a later regular file entry at the same archive path. The symlink target is not jailed to the extraction destination, and the later file open follows the symlink.</p>
<p>The attached PoC uses a two-entry `tar.gz` archive:</p>
<p>1. symlink `pwn -&gt; &lt;outside target&gt;`;
2. regular file `pwn` containing attacker-controlled bytes.</p>
<p>The same `mholt/archives` extraction flow is used for the vulnerable handler and for a negative-control handler using a destination-root jail.</p>
<p>### PoC</p>
<p>Attachment: `submission_aqua_archive_symlink_traversal_v2_final.zip`</p>
<p>Run:</p>
<p>```ba…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mf5c-hw34-4hpp"/>
  </entry>
</feed>
